Technology
Danish Kapoor
Danish Kapoor

OpenAI finds way to monitor security without storing customer data

OpenAI introduced its new security technology, called Private Safety Processing, to track possible misuse of artificial intelligence services without storing sensitive data of corporate customers. The system, which is currently in the preview phase with select customers, expands the scope of the company’s existing Zero Data Retention approach and can evaluate activities spanning multiple conversations instead of a single session. According to the information provided by OpenAI, this process is carried out automatically and the customer’s conversation data is not stored by the company. Thus, it is aimed to establish a different balance between privacy requirements and the need to detect the misuse of artificial intelligence, especially for businesses working with sensitive information. The new approach also differs significantly from Anthropic’s 30-day data retention policy for certain advanced models.

As the capabilities of artificial intelligence models increase, the possibility of these systems being used to develop malware, prepare cyber attacks or for other malicious purposes makes the security policies of technology companies more complex. On the corporate side, how these controls are carried out has become as sensitive an issue as security itself. When companies process trade secrets, source code, customer information or other sensitive data with AI models, they want to know how long it is kept by the model provider and who has access to it. OpenAI can currently perform session-by-session abuse checks without storing the data of eligible API customers under the approach known as Zero Data Retention, or ZDR. Private Safety Processing extends this mechanism to evaluate usage patterns over a longer period of time.

OpenAI Private Safety Processing can evaluate multiple conversations

The main difference of Private Safety Processing is that it does not keep the security assessment within the boundaries of a single API session. OpenAI describes the system as “long-horizon safety monitoring” and states that it can evaluate the inputs and outputs of multiple conversations together. The control is again carried out by an automated agent, and when certain conditions are met, interactions in different sessions are analyzed for signs of potential abuse. This method is designed to identify situations where malicious users try to evade the attention of security systems by splitting their requests into different sessions, an OpenAI spokesperson told TechCrunch. For example, someone trying to prepare malware that can be used in a cyberattack can distribute different parts of the transaction across separate sessions, rather than looking overtly suspicious in a single conversation.

According to OpenAI’s statement, when the system detects such a situation, it can send a narrowly defined signal to the company that only relates to a certain type of activity. At this stage, OpenAI can decide whether sanctions are required based on the signal in question, rather than opening all conversations to human review. If an intervention is assessed as necessary, the company can contact the relevant customer to gain further context or address the issue together. If deemed necessary, the customer can share additional data with OpenAI at his/her own discretion. Therefore, the distinguishing feature of the system is not only that it uses automation, but also that it aims to evaluate possible connections between different sessions without the need for OpenAI employees to directly examine customer conversations.

Anthropic’s approach differs especially in the models that the company defines as “covered models”. Under the policy announced in July, user sessions and conversations in these sessions can be stored for up to 30 days for Mythos class models and future models with similar capabilities. Anthropic states that this is implemented for security purposes and to enable investigation of possible improper use. However, this data retention period has attracted the reaction of some corporate customers who process high amounts of sensitive information. Although Anthropic generally supports Zero Data Retention applications, different data retention conditions may apply in systems within the scope of “covered models” such as Fable.

Anthropic makes it clear that customer data can also be reviewed by humans if necessary. According to the company, this access occurs through a controlled access channel that is only available to a small number of approved reviewers. In addition, each review session is transferred to a tamper-proof recording system that reviewers cannot delete or modify. Although this mechanism ensures that access is auditable, the issue of data retention does not disappear for businesses that do not want their data to be kept by the artificial intelligence provider. OpenAI’s Private Safety Processing approach, on the other hand, may offer a more suitable option, especially for organizations with strict data management policies, as it is based on not storing the conversation content while maintaining security analysis.

At a time when the competition between OpenAI and Anthropic is intensifying in the corporate artificial intelligence market, privacy policies are becoming one of the determining factors as much as the performance and pricing of the models. According to a recent report, OpenAI’s growth in the second quarter fell behind Anthropic’s, while Anthropic’s annualized revenue pace reportedly reached $65 billion. It is reported that Anthropic investors are talking about an IPO valuation that could reach up to $2 trillion for the company, and that OpenAI is also working on its own IPO. In addition to this financial competition, the data storage and security options offered by companies to corporate customers can also have a direct impact on service selection. The success of Private Safety Processing will depend not only on how accurately it detects abuse, but also on how technically and operationally it can demonstrate that customer data is not actually being stored, while keeping false positives low.

TechGIndia is now on WhatsAppGet the best technology deals of the day and big news you shouldn’t miss, delivered to your phone.

Join Channel

Danish Kapoor